Secure Route Establishment in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ad hoc wireless networks face inefficiencies in authentication processes due to the need for complex mutual authentication between all neighboring nodes, consuming significant time and processor resources, especially in scenarios without traditional infrastructure like base stations.
Innovation Solution
A method that allows nodes in a wireless network to selectively form security associations with only particular neighboring nodes, using route request and reply messages to establish ephemeral and secure routes, and employing multi-class routing tables to differentiate between secure and non-secure links, thereby reducing unnecessary authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex mutual authentication is performed between all neighboring nodes in ad hoc wireless networks, then security is improved, but time consumption and processor resource usage increase significantly
Solution Approach 1:
The patent extracts the authentication requirement from being universally applied to all neighboring nodes and selectively applies it only to nodes that form security associations. This is achieved by having nodes maintain authentication states and selectively authenticating only with specific neighbors rather than all neighbors, thereby reducing authentication time while maintaining security where needed.
Solution Approach 2:
Instead of performing complete mutual authentication with all neighboring nodes, the patent implements partial authentication only with nodes that require security associations. Nodes can communicate with non-authenticated neighbors using unsecured links for non-sensitive data, performing authentication only partially with specific nodes rather than all nodes, reducing overall authentication time and processor usage.
2Reliability
If complex mutual authentication is performed between all neighboring nodes in ad hoc wireless networks, then security is improved, but processor resource consumption increases significantly
Solution Approach 1:
The patent extracts the authentication requirement from being universally applied to all neighboring nodes and selectively applies it only to nodes that form security associations. This is achieved by having nodes maintain authentication states and selectively authenticating only with specific neighbors rather than all neighbors, thereby reducing processor resource consumption while maintaining security where needed.
Solution Approach 2:
Instead of performing complete mutual authentication with all neighboring nodes, the patent implements partial authentication only with nodes that require security associations. Nodes can communicate with non-authenticated neighbors using unsecured links for non-sensitive data, performing authentication only partially with specific nodes rather than all nodes, reducing overall processor resource consumption and energy usage.
3Device complexity
If centralized authentication procedure is used with a single IAP for all supplicants, then authentication management is simplified, but the system becomes impractical for nodes outside wireless range of IAP
Solution Approach 1:
The patent segments the centralized authentication architecture into distributed authentication capabilities. Each node in the ad hoc network can independently perform authentication with its neighbors, rather than all nodes depending on a single centralized IAP. This segmentation allows nodes outside IAP range to participate in the network while maintaining authentication security through peer-to-peer authentication mechanisms.
Solution Approach 2:
The patent introduces authentication state information as an intermediary mechanism that enables nodes to determine whether authentication is needed before communication. Nodes exchange authentication state information to identify which neighbors require security associations, allowing the system to adapt between centralized and distributed authentication modes depending on network conditions and node capabilities.
Data Source
AI summary
A method for establishing a secure route in a wireless network as provided improves network efficiency. According to one aspect, the method includes receiving at a first node in the wireless network a route request message from a second node, where the second node and the first node have not been mutually authenticated. The route request message is then forwarded from the first node to a third node. A route reply message is then received at the first node from the third node. The first node is then mutually authenticated with the second node in response to receiving the route reply message at the first node.


